WalletD developers
Catalog

Register a webhook endpoint for this merchant; the signing secret is returned once

Registers a webhook endpoint that receives only this merchant's events.

POST/v1/clients/{clientId}/webhook_endpoints

Registers a webhook endpoint that receives only this merchant's events. The signing secret is returned here and nowhere else. event_filters narrows what is delivered; omit it for every event the merchant can see. Needs authority over the client — membership of its organization, an API key bound to this client, or tenant staff holding clients:manage; anything else is refused not_client_member or insufficient_scope (403), and an unknown client client_not_found (404). A merchant-bound API key may register its own endpoints, which is the point; it still cannot touch the tenant-wide webhook surface. A missing body or a URL the service will not accept gives invalid_request (400).

Authorization

bearerAuth
AuthorizationBearer <token>

A tenant API key (sk_{env}_{id}_{secret}), a wallet user token, or an IdP access token. Which principal the credential resolves to decides the scopes it carries; see the authentication guide.

In: header

Path Parameters

clientId*string
Formatuuid

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

curl -X POST "https://example.com/v1/clients/497f6eca-6276-4993-bfeb-53cbbbba6f08/webhook_endpoints" \  -H "Content-Type: application/json" \  -d '{    "url": "http://example.com"  }'
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "client_id": "5b3fa7ba-57d3-4017-a65b-d57dcd2db643",  "url": "string",  "event_filters": [    "string"  ],  "status": "string",  "secret": "string",  "created_at": "2019-08-24T14:15:22Z"}